HomeRisk ManagementsEmerging Ransomware Gang Threatens Backup Destruction

Emerging Ransomware Gang Threatens Backup Destruction

Published on

spot_img

New Ransomware Group n0n Threatens to Destroy Backup Infrastructure

A newly formed ransomware group, named n0n, has emerged as a significant threat to organizations that fail to meet its extortion demands. This group has made alarming claims: if victims do not pay the ransom, n0n threatens to destroy their backup infrastructure. Such actions could completely incapacitate the targeted organization, leaving it unable to operate.

Cybersecurity researchers from CyberXTron recently detailed the activities of this emerging ransomware crew. In a blog post published on September 23, 2023, they revealed that n0n’s activity was first detected on September 18. By September 22, the group’s Tor-hosted leak site had already published data on over a dozen victims, indicating a rapid escalation in their operations.

N0n employs a double-extortion model, a tactic increasingly prevalent among ransomware threat groups. This model not only involves the theft of sensitive corporate data but also leverages explicit threats to encrypt or destroy backups and shadow copies of data. Such calculated intimidation tactics aim to instill terror among victims, with the intention of compelling them to pay the ransom to avoid losing their capacity to recover critical data.

Victim Profile and Sector Targeting

In their ongoing campaign, n0n has primarily targeted the financial services sector, which accounts for 23% of confirmed victims. Other sectors, such as technology, retail, and education, follow closely behind, with each representing 15% of victims. Furthermore, organizations within healthcare, defense, and professional services have also become targets of this malicious group. While the most frequent targets for n0n ransomware attacks are based in the United States, victims have also been reported across various countries, including Vietnam, Uzbekistan, Brazil, Sweden, and Luxembourg.

A particularly concerning psychological tactic employed by n0n is the use of countdown timers associated with victims. These timers are designed to create a sense of urgency, aiming to incite fear and motivate targeted organizations into making payments. In some instances, these countdowns have already expired, and data stolen during the attacks has been publicly released. This indicates that, despite the ominous threats posed by n0n, some organizations are resolutely choosing not to comply with the extortion demands.

Methodology of Attack: Initial Entry via Stolen Credentials

Researchers at CyberXTron have assessed that n0n ransomware attacks typically begin through the exploitation of compromised credentials, often obtained via third-party infostealer malware. Once these credentials are in hand, attackers gain initial access to corporate networks and escalate their privileges to gain control of administrative tools. This manipulation allows them to stage data in preparation for their extortion demands.

Given the increasing sophistication and aggressiveness of n0n’s tactics, CyberXTron has urged organizations to consider n0n as an active and credible double-extortion threat that requires immediate action. They emphasize the importance of maintaining stringent credential hygiene, active monitoring of access, and ensuring the isolation of backups.

Recommended Best Practices to Mitigate Risk

To counter the rising threat posed by n0n and similar ransomware groups, CyberXTron advises organizations to implement a series of robust cybersecurity measures. These recommended actions include:

  1. Enforcing Multi-Factor Authentication (MFA): This should be applied across all entry points to external access, significantly enhancing security against unauthorized access.

  2. Restricting Exposure of Internet-Facing Services: Limiting the accessibility of services such as VPN, RDP, and remote access interfaces can significantly reduce vulnerability to attacks.

  3. Implementing Strict Least-Privilege Access Controls: This principle ensures that users have the minimum level of access necessary for their roles, thus limiting potential attack vectors.

  4. Segmenting Networks: Isolating critical systems and sensitive data environments can help contain any potential breaches.

  5. Monitoring Internal Access Behavior: Keeping a close watch on internal access patterns for signs of unauthorized lateral movement or privilege misuse is crucial in detecting and responding to threats before they escalate.

As organizations face increasing challenges from sophisticated cyber threats, the emergence of groups like n0n underscores the necessity of robust cybersecurity measures. Failed responses to these threats could lead not only to data loss but also to devastating impacts on business operations—a reality that organizations can no longer afford to ignore.

Source link

Latest articles

Microsoft Integrates SOC Capabilities with Defender for Enterprises

On September 23, Microsoft announced a significant update to its Defender portals, introducing case...

OpenAI Agent Breached Australia’s Medicare Portal Undetected for Three Months

In a startling incident that underscores the emerging challenges surrounding artificial intelligence, an autonomous...

Cyber Briefing – September 24, 2026 – CyberMaterial

Cyber Briefing: Weekday Insights on Cybersecurity Developments In today's rapidly evolving digital landscape, the world...

More like this

Microsoft Integrates SOC Capabilities with Defender for Enterprises

On September 23, Microsoft announced a significant update to its Defender portals, introducing case...

OpenAI Agent Breached Australia’s Medicare Portal Undetected for Three Months

In a startling incident that underscores the emerging challenges surrounding artificial intelligence, an autonomous...